Splunk Enterprise

How to move index buckets from one host to another

highsplunker
Contributor

Hey guys,

could you please help and clarify this paragraph from the docs:


https://docs.splunk.com/Documentation/Splunk/8.1.1/Installation/MigrateaSplunkinstance
“When you copy individual bucket files, you must make sure that no bucket IDs conflict on the new system. Otherwise, Splunk Enterprise does not start. “


I’m not quite sure how this can happen?

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

As the documentation says, to avoid collisions rename the copied (copy rather than move avoids the need to move back) buckets on the target system.  The last set of digits in the bucket name is the bucket ID so make sure those are always unique within an index.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

As the documentation says, to avoid collisions rename the copied (copy rather than move avoids the need to move back) buckets on the target system.  The last set of digits in the bucket name is the bucket ID so make sure those are always unique within an index.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

It can happen if buckets are copied from one Splunk instance to another, which may have existing buckets on it.

It is not a concern when moving data to a brand-new instance.

---
If this reply helps you, Karma would be appreciated.

highsplunker
Contributor

Hello Rich!

(I don't have the problem, but I'm preparing to move some old index data, and I read this page. That's why I'm asking, disturbed a little bit.)

If I'm correct the quick remedy is to remove back those new folders I placed in db storage of my new Splunk server. I mean its bad to have the instance down.

But how can I avoid the collision? Maybe by appropriate naming of new buckets or directories?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...